CVE-2017-3159
published 2017-03-07CVE-2017-3159: Apache Camel's camel-snakeyaml component is vulnerable to Java object de-serialization vulnerability. De-serializing untrusted data can lead to security flaws.
PriorityP353critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
6.29%
92.8th percentile
Apache Camel's camel-snakeyaml component is vulnerable to Java object de-serialization vulnerability. De-serializing untrusted data can lead to security flaws.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | camel | <= 2.14.4 | — |
| apache | camel | — | — |
| apache | camel | 2.17.0 – 2.17.4 | — |
| apache | camel | 2.18.0 – 2.18.1 | — |
| apache_software_foundation | apache_camel | — | — |
| apache_software_foundation | apache_camel | — | — |
| apache_software_foundation | apache_camel | — | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_apache9.8MEDIUM
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
camel-snakeyaml: Unmarshalling operation is vulnerable to RCE
vendor_redhat·2016-12-08·CVSS 9.8
CVE-2017-3159 [CRITICAL] CWE-502 camel-snakeyaml: Unmarshalling operation is vulnerable to RCE
camel-snakeyaml: Unmarshalling operation is vulnerable to RCE
Apache Camel's camel-snakeyaml component is vulnerable to Java object de-serialization vulnerability. De-serializing untrusted data can lead to security flaws.
It was found that the camel-snakeyaml component is exploitable for code execution. An attacker could use this vulnerability to send specially crafted payload to a camel-snakeyaml endpoint and causing a remote code execution attack.
Package: camel-snakeyaml (Red Hat JBoss Fuse 6) - Affected
Apache
Apache camel: CVE-2017-3159
vendor_apache·CVSS 9.8
CVE-2017-3159 [MEDIUM] Apache camel: CVE-2017-3159
Apache camel: CVE-2017-3159
2.17.0 up to 2.17.4, 2.18.0 up to 2.18.1 2.17.5, 2.18.2 and newer MEDIUM Apache Camel's Snakeyaml unmarshalling operation is vulnerable to Remote Code Execution attacks 2016
Severity: medium
GHSA
Apache Camel's camel-snakeyaml component is vulnerable to Java object de-serialization
ghsa·2018-10-16
CVE-2017-3159 [CRITICAL] CWE-502 Apache Camel's camel-snakeyaml component is vulnerable to Java object de-serialization
Apache Camel's camel-snakeyaml component is vulnerable to Java object de-serialization
Apache Camel's camel-snakeyaml component is vulnerable to Java object de-serialization. De-serializing untrusted data can lead to security flaws.
OSV
Apache Camel's camel-snakeyaml component is vulnerable to Java object de-serialization
osv·2018-10-16
CVE-2017-3159 [CRITICAL] Apache Camel's camel-snakeyaml component is vulnerable to Java object de-serialization
Apache Camel's camel-snakeyaml component is vulnerable to Java object de-serialization
Apache Camel's camel-snakeyaml component is vulnerable to Java object de-serialization. De-serializing untrusted data can lead to security flaws.
No detection rules found.
No public exploits indexed.
http://camel.apache.org/security-advisories.data/CVE-2017-3159.txt.asc?version=1&modificationDate=1486565167000&api=v2http://www.openwall.com/lists/oss-security/2017/05/22/2http://www.securityfocus.com/bid/96321https://access.redhat.com/errata/RHSA-2017:0868https://lists.apache.org/thread.html/2318d7f7d87724d8716cd650c21b31cb06e4d34f6d0f5ee42f28fdaf%40%3Ccommits.camel.apache.org%3Ehttps://lists.apache.org/thread.html/b4014ea7c5830ca1fc28edd5cafedfe93ad4af2d9e69c961c5def31d%40%3Ccommits.camel.apache.org%3Ehttps://www.github.com/mbechler/marshalsec/blob/master/marshalsec.pdf?raw=truehttp://camel.apache.org/security-advisories.data/CVE-2017-3159.txt.asc?version=1&modificationDate=1486565167000&api=v2http://www.openwall.com/lists/oss-security/2017/05/22/2http://www.securityfocus.com/bid/96321https://access.redhat.com/errata/RHSA-2017:0868https://lists.apache.org/thread.html/2318d7f7d87724d8716cd650c21b31cb06e4d34f6d0f5ee42f28fdaf%40%3Ccommits.camel.apache.org%3Ehttps://lists.apache.org/thread.html/b4014ea7c5830ca1fc28edd5cafedfe93ad4af2d9e69c961c5def31d%40%3Ccommits.camel.apache.org%3Ehttps://www.github.com/mbechler/marshalsec/blob/master/marshalsec.pdf?raw=true
2017-03-07
Published